A Look at the ECS Behavior of DNS Resolvers

A Look at the ECS Behavior of DNS Resolvers
复制标题

DOI:
10.1145/3355369.3355586
复制
发表时间:
2019-10
期刊:
Proceedings of the Internet Measurement Conference
影响因子:
--
通讯作者:
R. Al-Dalky;M. Rabinovich;Kyle Schomp
R. Al-Dalky;M. Rabinovich;Kyle Schomp
中科院分区:
其他
文献类型:
--
作者:
R. Al-Dalky;M. Rabinovich;Kyle Schomp

文献摘要

相似文献

内容分发网络(CDN)通常使用DNS将最终用户映射到最佳边缘服务器。最近提出的EDNS 0-Client-Subnet(ECS)扩展允许递归解析器在DNS查询中包含最终用户子网信息,以便权威DNS服务器(特别是属于CDN的服务器)可以使用此信息来改进用户映射。在本文中,我们从DNS交互的相对方、主要CDN的权威DNS服务器和繁忙的忙碌解析服务的角度研究了启用ECS的递归解析器的ECS行为。我们发现一系列错误(即,偏离协议规范)和有害(即使是兼容的)行为,这些行为可能不必要地侵蚀客户端隐私、降低DNS缓存的有效性、减少ECS益处,并且在某些情况下将ECS从促进者变成权威DNS服务器优化用户到边缘服务器映射的能力的障碍。
Content delivery networks (CDNs) commonly use DNS to map end-users to the best edge servers. A recently proposed EDNS0-Client-Subnet (ECS) extension allows recursive resolvers to include end-user subnet information in DNS queries, so that authoritative DNS servers, especially those belonging to CDNs, could use this information to improve user mapping. In this paper, we study the ECS behavior of ECS-enabled recursive resolvers from the perspectives of the opposite sides of a DNS interaction, the authoritative DNS servers of a major CDN and a busy DNS resolution service. We find a range of erroneous (i.e., deviating from the protocol specification) and detrimental (even if compliant) behaviors that may unnecessarily erode client privacy, reduce the effectiveness of DNS caching, diminish ECS benefits, and in some cases turn ECS from facilitator into an obstacle to authoritative DNS servers' ability to optimize user-to-edge-server mappings.